Documentation

What HCM Lens does, what to upload, how the analysis works, and how your data is handled.

Overview

HCM Lens turns your SAP HCM authorization exports into an explainable, prioritized access-risk ranking with audit-ready evidence.

Who it’s for

Internal audit, GRC / security teams, and SAP authorization owners.

What it does

Scores access risk transparently — every score is explained by its rules.

What you get

Prioritized risks (score + reason) and audit-ready exports.

Required SAP exports

The supported flow is SAP-native: export your SAP tables (XLSX or CSV, with their technical headers) and upload them as-is — no manual consolidation.

Core access exports

The role/access tables describing users, their role assignments, and the authorizations each role grants (plus role and transaction texts for readability).

Optional usage traces

An optional usage export (user × transaction × date) enables unused-permission detection with real evidence. Without it, that check is safely skipped.

Each file is read through a strict allowlist of expected columns; anything not listed — including any password-hash columns — is never read, parsed or stored. Files are processed in memory and discarded.

How the analysis works

  1. 1 Upload your SAP exports (optional usage file included).
  2. 2 Preflight — each file is validated against its expected structure.
  3. 3 Dry-run — preview what would be imported and scored; nothing is persisted.
  4. 4 Upload & scoring — confirm to persist an immutable run and compute the ranking.
  5. 5 Review — browse prioritized users and roles; every score is explained.
  6. 6 Compare runs — see how risk changed between two analyses (A/B).
  7. 7 Export — download audit-ready rankings.

Security & privacy

  • No raw retention: files are processed in memory and never written to disk at the app layer.
  • Pseudonymization: SAP user identifiers are keyed-HMAC pseudonymized, and encrypted at rest where stored.
  • Tenant isolation: one organization can never see another organization’s data.
  • Value-free diagnostics: warnings and errors never echo SAP ids, cell values or filenames.
  • No SAP secrets accepted: password hashes and similar columns are rejected by design.
  • Invitation-only access: there is no public sign-up; accounts are provisioned manually.

Demo & access

Request a demo by email. Access is provisioned manually by invitation.

Request demo → we review → we provision a demo/trial organization and send an invitation → production access follows an agreement. There is no self-service registration.

Request a demo

FAQ

Do I need to install anything in SAP?

No. You upload standard SAP table exports; nothing is installed in your SAP system.

Can I upload real data?

Only with a lawful basis. Processing real employee data requires internal authorization and an applicable data processing agreement (DPA); for evaluation, use synthetic or anonymized exports. In all cases files are processed in memory and discarded, and identifiers are pseudonymized.

What happens to the raw files?

They are parsed in memory and not retained at the application layer.

Which file formats are supported?

XLSX and CSV exports with technical SAP headers.

Can I compare runs?

Yes — compare any two analyses (A/B) to see how access risk evolved.

Is there a public sign-up?

No. Access is invitation-only, provisioned manually after a demo request.